VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10350CVEs
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2021-26623
Bandisoft ARK Library Out-of-bound Vulnerability
Published 2022-04-01 · Modified
9.8EPSS 0.011
CVE-2023-5168
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Published 2023-09-27 · Modified
9.8EPSS 0.011
CVE-2024-6912
Hardcoded MSSQL Credentials
Published 2024-07-22 · Modified
9.8EPSS 0.011
CVE-2022-22485
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.
Published 2022-06-17 · Modified
9.8EPSS 0.011
CVE-2025-49217
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
Published 2025-06-17 · Analyzed
9.8EPSS 0.011
CVE-2024-20738
Adobe FrameMaker Publishing Server Authentication Bypass Vulnerability | CVE-2023-44324 bypass
Published 2024-02-15 · Modified
9.8EPSS 0.011
CVE-2025-23304
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Published 2025-08-13 · Analyzed
9.8EPSS 0.011
CVE-2022-24955
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
Published 2022-02-11 · Modified
9.8EPSS 0.011
CVE-2021-26605
unidocs ezPDFReader arbitrary command execution vulnerability
Published 2021-08-05 · Modified
9.8EPSS 0.010
CVE-2026-8505
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
Published 2026-07-17 · Modified
9.8EPSS 0.010
CVE-2023-29486
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue, not a Heimdal specific vulnerability. The USB control solution by Heimdal is meant to manage Microsoft Windows native USB restrictions. They maintain that their solution functions as a management layer over Windows settings and is not to blame for limitations in Windows' detection capabilities.
Published 2023-12-21 · Modified
9.8EPSS 0.010
CVE-2021-26618
Tmax ToOffice arbitrary file creation vulnerability
Published 2022-02-18 · Modified
9.8EPSS 0.010
CVE-2023-35174
Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows
Published 2023-06-22 · Modified
9.8EPSS 0.010
CVE-2022-23769
Secuever reverseWall-MDS Remote Code Execution Vulnerability
Published 2022-10-17 · Modified
9.8EPSS 0.010
CVE-2025-34195
Vasion Print (formerly PrinterLogic) Unquoted Path During Driver Installation Leads to Execution of C:\Program.exe
Published 2025-09-19 · Modified
9.8EPSS 0.010
CVE-2026-8398
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
Published 2026-05-15 · Analyzed
9.8KEVEPSS 0.010
CVE-2023-29485
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention module. NOTE: Heimdal disputes the validity of this issue arguing that their DNS Security for Endpoint filters DNS traffic on the endpoint by intercepting system-generated DNS requests. The product was not designed to intercept DNS requests from third-party solutions.
Published 2023-12-21 · Modified
9.8EPSS 0.010
CVE-2020-7832
RAONWIZ DEXT5 Upload remote code execution vulnerability
Published 2021-09-07 · Modified
9.8EPSS 0.010
CVE-2022-23767
SecureGate authentication bypass vulnerability
Published 2022-09-19 · Modified
9.8EPSS 0.009
CVE-2026-48333
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-08-03 · Analyzed
9.8EPSS 0.009
CVE-2023-29542
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Published 2023-06-19 · Modified
9.8EPSS 0.009
CVE-2020-7883
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.
Published 2021-12-28 · Modified
9.8EPSS 0.009
CVE-2021-39085
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.
Published 2022-08-16 · Modified
9.8EPSS 0.009
CVE-2024-33868
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
Published 2024-05-14 · Analyzed
9.8EPSS 0.009
CVE-2025-69269
Spectrum command injection in NCM service
Published 2026-01-12 · Analyzed
9.8EPSS 0.009
CVE-2020-4877
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
Published 2022-01-21 · Modified
9.8EPSS 0.009
CVE-2020-36639
AlliedModders AMX Mod X Console Command adminvote.sma cmdVoteMap path traversal
Published 2023-01-04 · Modified
9.8EPSS 0.009
CVE-2021-26644
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.
Published 2023-01-20 · Modified
9.8EPSS 0.009
CVE-2023-23459
Priority Windows – Command Execution via SQL Injection
Published 2023-02-15 · Modified
9.8EPSS 0.009
CVE-2026-8855
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.8EPSS 0.008
CVE-2023-30268
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
Published 2023-05-04 · Modified
9.8EPSS 0.008
CVE-2022-2778
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
Published 2022-09-30 · Modified
9.8EPSS 0.008
CVE-2020-7853
TOBESOFT XPLATFORM Out-of-Bounds Read/Write Vulnerabilities
Published 2021-03-24 · Modified
9.8EPSS 0.008
CVE-2024-8196
Missing Authentication for Critical Function in mintplex-labs/anything-llm
Published 2025-03-20 · Analyzed
9.8EPSS 0.008
CVE-2023-0925
Software AG webMethods OneData Deserialization Vulnerability
Published 2023-09-06 · Modified
9.8EPSS 0.008
CVE-2021-26630
HANDY Groupware file download and execute vulnerability
Published 2022-05-19 · Modified
9.8EPSS 0.008
CVE-2025-34193
Vasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated Runtimes
Published 2025-09-19 · Modified
9.8EPSS 0.008
CVE-2023-0575
Remote Code Execution
Published 2023-02-09 · Modified
9.8EPSS 0.008
CVE-2024-39747
IBM Sterling Connect:Direct Web Services information disclosure
Published 2024-08-31 · Analyzed
9.8EPSS 0.008
← Prev34 / 259Next →